CVE-2020-8987
09.03.2020, 17:15
Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certificate. No special action necessary by the victim using AntiTrack with "Allow filtering of HTTPS traffic for tracking detection" enabled. (This is the default configuration.)Enginsight
Vendor | Product | Version |
---|---|---|
avast | antitrack | 𝑥 < 1.5.1.172 |
avast | avg_antitrack | 𝑥 < 2.0.0.178 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References